HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics Phishing Attack Affecting 225,000 Individuals - Report - MDSpire
Coming Soon: Introducing MDSpire News. Learn more
Conexiant’s news site is now MDSpire News. Learn more

HHS Office for Civil Rights Reaches Settlement with Ambry Genetics Over HIPAA Breach Linked to Phishing Incident Impacting 225,000 Patients

  • By

  • Office for Civil Rights (OCR)

  • September 17, 2026

Share

Clinical Report: HHS Office for Civil Rights Reaches Settlement with Ambry Genetics

Overview

The HHS Office for Civil Rights has reached a settlement with Ambry Genetics over a HIPAA breach linked to a phishing incident affecting 225,370 patients. Ambry will pay $700,000 and implement a corrective action plan to address identified security deficiencies.

Background

The protection of patient health information is critical in healthcare, particularly in light of increasing cyber threats such as phishing attacks. The HIPAA Security Rule establishes essential standards for safeguarding electronic protected health information (ePHI).

Data Highlights

No numerical data or trial data available.

Key Findings

  • Ambry Genetics experienced a phishing attack that compromised an employee's email account.
  • Protected health information of 225,370 individuals was potentially exfiltrated, including names, addresses, and clinical details.
  • OCR identified violations related to risk analysis, termination of access, and user identification procedures.
  • Ambry agreed to a two-year corrective action plan and paid a settlement of $700,000.

Clinical Implications

Healthcare organizations must prioritize compliance with HIPAA regulations to protect patient information from cyber threats. Implementing robust risk management strategies and ensuring workforce training are essential steps in safeguarding ePHI.

Conclusion

The settlement with Ambry Genetics serves as a reminder of the ongoing risks associated with cybersecurity in healthcare and the necessity for stringent adherence to HIPAA Security Rule provisions.

Related Resources & Content

  1. United States Department of Health and Human Services, HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics Phishing Attack Affecting 225,000 Individuals, 2026 -- HHS Office for Civil Rights Settles HIPAA Investigation
  2. United States Department of Health and Human Services, HHS’ Office for Civil Rights Settles Ransomware Investigation with Health Plan, 2026 -- HHS’ Office for Civil Rights Settles Ransomware Investigation
  3. United States Department of Health and Human Services, HHS Office for Civil Rights Reaches Settlement with Azul Vision, Inc. Over HIPAA Access Investigation, 2026 -- HHS Office for Civil Rights Reaches Settlement
  4. ADA News, Nevada health system to pay $75,000 to settle potential HIPAA violation, 2021 -- Nevada health system to pay $75,000 to settle potential HIPAA violation
  5. ADA News — New York health insurer pays $5.1M to settle potential HIPAA violations
  6. HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics Phishing Attack Affecting 225,000 Individuals | HHS.gov
  7. Summary of the HIPAA Security Rule | HHS.gov
  8. Resolution Agreements | HHS.gov

Original Source(s)

Related Content